Radius-Based Mac Authentication Configuration Example - H3C S5500-SI Series Operation Manual

Hide thumbs Also See for S5500-SI Series:
Table of Contents

Advertisement

MAC address authentication is enabled
Authenticate success: 1, failed: 0
Current online user number is 1
MAC Addr
00e0-fc12-3456

RADIUS-Based MAC Authentication Configuration Example

Network requirements
As illustrated in
device authenticates, authorizes and keeps accounting on the host through the RADIUS server.
MAC authentication is required on every port to control user access to the Internet.
Set the offline detect timer to 180 seconds and the quiet timer to 3 minutes.
All users belong to ISP domain 2000.
The username type of fixed username is used for authentication, with the username being aaa and
password being 123456.
Figure 1-2 Network diagram for MAC authentication using RADIUS
Configuration procedure
It is required that the RADIUS server and the device are reachable to each other and the username and
password are configured on the server.
1)
Configure MAC authentication on the device
# Configure a RADIUS scheme.
<Device> system-view
[Device] radius scheme 2000
[Device-radius-2000] primary authentication 10.1.1.1 1812
[Device-radius-2000] primary accounting 10.1.1.2 1813
[Device-radius-2000] key authentication abc
[Device-radius-2000] key accounting abc
[Device-radius-2000] user-name-format without-domain
Authenticate state
MAC_AUTHENTICATOR_SUCCESS
Figure
1-2, a host is connected to the device through port GigabitEthernet 1/0/1. The
Auth Index
29
1-7

Advertisement

Chapters

Table of Contents
loading

Table of Contents